Data Processing Agreement

Last updated: July 13, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service or other written agreement between bry3d llc ("BRY3D" or "Processor") and the customer identified in the applicable account or order form ("Customer" or "Controller"). This DPA governs BRY3D's processing of Customer Personal Data on Customer's behalf and is intended to satisfy Article 28 of the GDPR and corresponding requirements of other applicable data-protection laws.

1. Subject matter and roles

2. Nature and purpose of processing

Subject matter: provision of the Services described in the Terms and the applicable order. Nature and purpose: collection, hosting, organization, storage, retrieval, consultation, use, transmission, display, automation, analysis, restriction, deletion, and other processing necessary to provide, secure, support, and maintain the Services configured by Customer. Duration: the term of the applicable Services and any limited period thereafter during which BRY3D processes Customer Personal Data in accordance with this DPA.

Categories of data subjects: the Customer's prospects and customers, website visitors interacting with the Customer's viewers, forms, or chat assistant, and the Customer's team members.

Categories of personal data: contact details (name, email, phone, address), company details, product configurations and quotes, order and job information, communications (email, chat, WhatsApp), documents and signatures, and technical data related to platform use. The platform is not intended for special categories of data (Art. 9 GDPR), and the Customer agrees not to store them in it.

3. Instructions

BRY3D shall process Customer Personal Data only on Customer's documented instructions, including the Terms, this DPA, the applicable order, Customer's configuration and use of the Services, and other written instructions acknowledged by BRY3D, unless processing is required by applicable law. If applicable law requires processing beyond Customer's instructions, BRY3D shall notify Customer before processing unless the law prohibits notice. BRY3D shall promptly inform Customer if, in BRY3D's opinion, an instruction violates applicable data-protection law.

4. Confidentiality and personnel

BRY3D ensures that persons authorized to process Customer Personal Data are bound by confidentiality obligations and access data only as needed for their role.

5. Security

BRY3D shall implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing. Current measures are described in the Security Statement. BRY3D may modify those measures provided that the modification does not materially reduce the overall security of the Services.

6. Sub-processors

Customer provides general written authorization for BRY3D to appoint the sub-processors listed below. BRY3D shall enter into a written agreement with each sub-processor imposing data-protection obligations no less protective than the obligations applicable to BRY3D under this DPA, to the extent relevant to the sub-processor's services. BRY3D remains responsible for the performance of each sub-processor as required by applicable law. BRY3D shall provide at least 14 days' prior notice of a new or replacement sub-processor. Customer may object during that period on reasonable, documented data-protection grounds. The parties shall cooperate in good faith to resolve the objection. If no commercially reasonable resolution is available, Customer may terminate the affected Services.

7. Current sub-processor list

Sub-processorPurposeSafeguard for non-EEA processing
SupabaseDatabase, authentication, file storageSCCs / DPF where applicable
VercelApplication hosting, delivery, web analytics, and performance measurementSCCs / DPF where applicable
StripePayment and subscription processingSCCs / DPF where applicable
SentryError monitoring and diagnosticsSCCs / DPF where applicable
OpenAI (or the AI provider configured for the account)AI assistant responsesSCCs / DPF where applicable
Meta Platforms (WhatsApp Business)WhatsApp messaging and lead integrations, when connected by the CustomerSCCs / DPF where applicable
GoogleCalendar and Drive integrations, when connected by the CustomerSCCs / DPF where applicable
n8nWorkflow automation between connected servicesSCCs / DPF where applicable

Integrations the Customer connects itself (for example its own email account, accounting tool, or a self-supplied AI key) act on the Customer's behalf and under the Customer's own agreement with that provider.

8. International transfers

Customer authorizes transfers of Customer Personal Data to the United States and other jurisdictions in which BRY3D or its authorized sub-processors operate. For restricted transfers subject to the GDPR, the parties incorporate the European Commission Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914, Module Two (Controller to Processor), with Customer as data exporter and BRY3D as data importer, unless another lawful transfer mechanism applies. For restricted transfers subject to the UK GDPR, the applicable UK International Data Transfer Addendum is incorporated. BRY3D shall implement supplementary measures where required by applicable law.

9. Assistance

10. Personal data breaches

BRY3D notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the information reasonably needed for the Customer's own notification obligations, and cooperates in investigating and mitigating the breach.

11. Deletion and return

During the term, Customer may export Customer Personal Data using available Service functionality. Upon termination or expiration of the Services, and at Customer's election where required by applicable law, BRY3D shall return or delete Customer Personal Data within 30 days, except to the extent retention is required by applicable law. Residual copies maintained in backups will be isolated from ordinary use and deleted in accordance with BRY3D's backup-retention cycle.

12. Audits

BRY3D shall make available information reasonably necessary to demonstrate compliance with Article 28 GDPR. Customer may conduct an audit, including an inspection, itself or through an independent auditor bound by confidentiality, no more than once in any 12-month period unless required by a supervisory authority or following a confirmed personal data breach. Customer shall provide at least 30 days' prior written notice, conduct the audit during normal business hours, avoid unreasonable disruption, and reimburse BRY3D's reasonable costs unless the audit identifies material noncompliance.

13. Liability and precedence

Liability under this DPA is governed by the limitation of liability in the Terms of Service. If this DPA conflicts with the Terms, this DPA prevails for data-protection matters. Translations are provided for convenience; the English version prevails.

14. Contact

Data-protection notices must be directed to admin@bry3d.com and to bry3d llc, 117 S Lexington Street, Suite 100, Harrisonville, Missouri 64701, United States.

This DPA may be accepted electronically as part of the Terms of Service. Electronic acceptance constitutes execution by the parties.